[ Applies to ] StorageGuard 9.x and later / Veeam Backup & Replication (VBR) / VBR server (Windows)
StorageGuard collects configuration data from Veeam Backup & Replication (VBR) by running read-only REST API calls and Veeam PowerShell cmdlets on the VBR server. As part of the scan, StorageGuard also runs Veeam's Security & Compliance Analyzer. This article describes the requirements and how to create the scan account.
In this article
Requirements
| Requirement | Details |
|---|---|
| Server address | The network name or IP address of the VBR server. |
| OS account | A Windows user with remote management privileges on the VBR server. |
| Veeam role | The Veeam Backup Administrator role. See Choose a Veeam role. |
| REST API | The user must be able to run REST API GET requests (port 9419 by default), such as /api/v1/generalOptions, /api/v1/serverCertificate, /api/v1/kmsServers, /api/v1/jobs, and /api/v1/restorePoints. |
| PowerShell | Windows PowerShell 5.1 or later on the VBR server. The user must be able to run read-only Veeam PowerShell cmdlets, such as Get-VBRMailNotificationConfiguration and Get-VESPSmtpSettings. |
| Network access | WinRM (ports 80 and 5985) and CIFS (port 445) from the StorageGuard server to the VBR server. If your organization doesn't use WinRM, allow WMI on all TCP ports and on UDP ports 135, 137, 138, and 139. |
Choose a Veeam role
| Role | What StorageGuard can check |
|---|---|
| Veeam Backup Administrator (recommended) | All checks. Some REST API calls, such as /api/v1/generalOptions and /api/v1/kmsServers, require this role. |
| Veeam Backup Viewer | A limited set of checks. This role doesn't currently provide access to all the configuration data needed for a complete security analysis. |
Create a scan account
The following procedure is a suggested way to create the scan account. The example uses the user name sguard; you can use any user name.
- Create a Windows user named sguard.
- Grant the user remote management privileges on the VBR server.
-
On the VBR server, run the following PowerShell command to assign the user the Veeam Backup Administrator role:
Add-VBRUserRoleAssignment -Name sguard -Role BackupAdmin
[ Still need help? ]
Our support team is here for you. Submit a request
Comments
0 comments
Please sign in to leave a comment.